A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #9385  by rkhunter
 Mon Oct 24, 2011 10:26 am
AaLl86 wrote:Hi All!
As many of you know, TDL4 has now evolved. Now it installs an hidden partition without touching MBR code.
Try to check this article: http://blog.eset.com/2011/10/18/tdl4-rebooted.
I would like to ask if somebody can post here the new dropper.


Thank you all very much.
Andrea
Actually, this is not original TDL4, it's modification - MaxSS (Trojan:Win32/Alureon.FE). Sample can be found at "TDL Modifications" branch, look http://www.kernelmode.info/forum/viewto ... 8758#p8758.
 #9457  by shreyas
 Sun Oct 30, 2011 3:18 pm
http://www.virustotal.com/file-scan/rep ... 1316544567

a another varient of TDL4....low detection... :)

moddersondazone.com/random/trol.exe

1 day old TDL4...on my Vm...still i am struggling to gain access to the Vm to commence repairs....

Use Edit button next time.
Last edited by EP_X0FF on Sun Oct 30, 2011 3:55 pm, edited 1 time in total. Reason: edit
 #9460  by EP_X0FF
 Sun Oct 30, 2011 4:00 pm
Hello shreyas,

1. Please avoid posting of non meaningful replies and start to use Edit button.
2. It is good that you know about MDL existence, we are too, no need to re-post links from MDL.
3. This MDL sample is 2+ weeks old.
4. LDR16 as file detection is not really important.
 #9464  by EP_X0FF
 Mon Oct 31, 2011 5:45 am
shreyas wrote:sorry! but that TDL4 is 2 days old....
Oh, really?
MD5: 56bb50af9f67fd6efc16728fbea2c529
Date first seen: 2011-10-10 16:36:08 (UTC)
Date last seen: 2011-10-30 20:46:39 (UTC)
Detection ratio: 38/42
http://www.virustotal.com/file-scan/rep ... 1320039266
  • 1
  • 53
  • 54
  • 55
  • 56
  • 57
  • 60